Compatibility matrix
Splunk Enterprise Security version 8.x is compatible with Splunk Enterprise (on-prem) version 9.2.0 and higher.
Splunk Enterprise Security 8.0.x and 8.1.x are FedRAMP High compliant. FedRAMP Moderate meets Federal Information Processing Standard (FIPS) 199 Moderate Impact Level standards and Splunk Enterprise Security 8.x FedRAMP High meets Federal Information Processing Standard (FIPS) 199 High Impact Level standards. For current compliance information, see Compliance at Splunk.
For more information on the compatibility of Splunk Enterprise Security with Splunk Platform, Splunk IT Service Intelligence (ITSI), and Splunk IT Essentials (ITE) Work, see Splunk products version compatibility matrix.
For information on the eligibility requirements for behavioral analytics service with Splunk Enterprise Security, see What do I need to run behavioral analytics service in the Use Splunk Enterprise Security Manual.
Behavioral analytics is a Cloud-only service.
Splunk SOAR compatibility
Splunk SOAR pairs with Splunk Enterprise Security to let users run actions, run playbooks, and review automation history in Splunk Enterprise Security.
The following versions of Splunk SOAR are compatible with this version of Splunk Enterprise Security:
Splunk Enterprise Security deployment type | Compatible version of Splunk SOAR (Cloud) |
Compatible version of Splunk SOAR (On-premises) |
---|---|---|
Cloud | 6.3.0 and higher | --- |
On-premises | --- | 6.4.1 |
Threat Intelligence Management (Cloud) compatibility and regional availability
Threat Intelligence Management (Cloud) is accessible from within Splunk Enterprise Security to provide intelligence support for users.
To access Threat Intelligence Management (Cloud) within Splunk Enterprise Security, you must:
- Have a compatible licensed version of Splunk Enterprise Security
- Reside in an available region
Compatibility
Threat Intelligence Management (Cloud) supports search head cluster (SHC) deployments of Splunk Enterprise Security. See the following table for version compatibility with Threat Intelligence Management (Cloud):
Splunk Enterprise Security deployment type | Compatible version of Splunk Enterprise Security |
---|---|
Cloud | 6.6 or higher |
Threat Intelligence Management (Cloud) is not available for use with Splunk Enterprise Security preview or limited release versions.
Available regions
AWS region | Geographic area |
---|---|
us-east-1 | N. Virginia |
us-west-2 | Oregon |
ap-sourtheast-2 | Sydney |
ap-northeast-1 | Tokyo |
ap-southeast-1 | Singapore |
ca-central-1 | Montréal |
eu-central-1 | Frankfurt |
eu-west-2 | London |
eu-west-1 | Ireland |
eu-west-3 | Paris |
If you meet the above criteria, Threat Intelligence Management (Cloud) is automatically included with Splunk Enterprise Security cloud deployments and can be set up by an admin. See Overview of threat intelligence in Splunk Enterprise Security in the Administer Splunk Enterprise Security manual.
Limitations | How to find answers and get help with Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 8.1.0
Feedback submitted, thanks!